Micro Focus Novell Service Desk prior to 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
novell service desk |